CVE-2024-32236
- EPSS 0.05%
- Veröffentlicht 25.04.2024 17:15:49
- Zuletzt bearbeitet 14.04.2025 13:47:26
An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.
CVE-2024-32163
- EPSS 0.07%
- Veröffentlicht 17.04.2024 19:15:08
- Zuletzt bearbeitet 14.04.2025 13:43:41
CMSeasy 7.7.7.9 is vulnerable to code execution.
CVE-2024-32162
- EPSS 0.1%
- Veröffentlicht 17.04.2024 19:15:08
- Zuletzt bearbeitet 14.04.2025 13:43:17
CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.
CVE-2024-25828
- EPSS 0.14%
- Veröffentlicht 22.02.2024 16:15:54
- Zuletzt bearbeitet 03.04.2025 13:18:40
cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.
CVE-2024-0523
- EPSS 0.05%
- Veröffentlicht 14.01.2024 23:15:28
- Zuletzt bearbeitet 21.11.2024 08:46:47
A vulnerability was found in CmsEasy up to 7.7.7. It has been declared as critical. Affected by this vulnerability is the function getslide_child_action in the library lib/admin/language_admin.php. The manipulation of the argument sid leads to sql in...
CVE-2020-18406
- EPSS 0.07%
- Veröffentlicht 27.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:08:33
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.
CVE-2023-34880
- EPSS 0.17%
- Veröffentlicht 15.06.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:40
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.
CVE-2021-42644
- EPSS 0.36%
- Veröffentlicht 17.05.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:54
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.
CVE-2021-42643
- EPSS 0.44%
- Veröffentlicht 17.05.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:54
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.
CVE-2019-8434
- EPSS 0.21%
- Veröffentlicht 18.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:53
In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.